ClassroomPulse takes security seriously. We appreciate the security research community's efforts in helping keep our users safe. This policy outlines how to report vulnerabilities and what you can expect from us.
We encourage responsible disclosure of security vulnerabilities. To be eligible for recognition and potential rewards, please follow these guidelines:
Email: security@classroompulse.io
PGP Key: Available upon request
Response Time: Within 24 hours for critical issues
The following are within scope for vulnerability reports:
The following are outside the scope and should not be tested:
Severity | Description | Response Time |
---|---|---|
Critical | Remote code execution, data breach, authentication bypass | 24 hours |
High | Privilege escalation, sensitive data exposure | 48 hours |
Medium | Cross-site scripting, CSRF, limited data access | 7 days |
Low | Information disclosure, minor security misconfigurations | 30 days |
When you report a vulnerability to us, we commit to:
We appreciate the efforts of security researchers. With your permission, we will:
When conducting vulnerability research according to this policy, we consider this to be:
We will not pursue legal action against researchers who:
We maintain transparency about resolved security issues:
2025-01: Fixed XSS vulnerability in report generation (reported by: Anonymous)
2024-12: Resolved authentication bypass in API endpoint (reported by: Security Researcher)
2024-11: Patched SQL injection in search functionality (reported by: Bug Bounty Hunter)
Security Team Email: security@classroompulse.io
Urgent Security Line: (972) 439-5845
Bug Bounty Platform: Coming Soon
PGP Fingerprint: Available upon request
Note: For general support issues not related to security vulnerabilities, please contact support@classroompulse.io
This vulnerability disclosure policy is subject to change. Last updated: January 2025. Thank you for helping us keep ClassroomPulse secure for all users.